CVE-2026-59310

VMware · Cloud Foundation, vCenter, vSphere Foundation, Telco Cloud Infrastructure, Telco Cloud Platform

VMware vCenter contains a directory traversal vulnerability in the Syslog server, which may allow an unauthenticated attacker with network access to execute arbitrary code on the system.

Executive summary

A critical directory traversal vulnerability in the VMware vCenter Syslog server allows unauthenticated remote attackers to achieve arbitrary code execution.

Vulnerability

This is a directory traversal vulnerability (CWE-22) located in the Syslog server component. An unauthenticated attacker can leverage this flaw to access restricted directories and execute arbitrary code, compromising the underlying host.

Business impact

The ability for an unauthenticated attacker to execute code remotely carries a CVSS score of 9.8, indicating a critical risk of total system takeover. This could result in complete loss of control over the virtual infrastructure, data theft, or the installation of persistent malicious backdoors.

Remediation

Immediate Action: Upgrade all affected VMware components to the latest versions as specified in the official Broadcom security advisory.

Proactive Monitoring: Inspect Syslog server logs for path traversal patterns, such as sequences including dot-dot-slash, and monitor for unexpected process execution on the vCenter appliance.

Compensating Controls: Deploy a Web Application Firewall or network intrusion detection system to filter malicious payloads targeting the Syslog server interface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical severity and the potential for remote code execution, organizations must treat this vulnerability with the highest priority. Patching is the only effective way to remove the underlying defect and prevent potential exploitation.